Files
Gitea/models/auth/session.go
T
silverwind cf89ecd887 refactor!: move go-chi/session into Gitea (#39504)
The `gitea.com/go-chi/session` package only exists for Gitea, so it
moves into `modules/session` to fix its bugs directly. Fixes the flake
in
https://github.com/go-gitea/gitea/actions/runs/36726154500/job/109923538400.

- Sessions are only written back when changed, so a read-only request
can't revert a concurrent change or restore a logged-out session, like
https://github.com/go-macaron/session/commit/ae808a4a4660c802965c834299ab08f167effd12
- The session cookie is only set once a session holds data
- Every backend refreshes the expiry on load and file sessions are
written atomically
- Also fix  https://github.com/go-gitea/gitea/issues/36176

## ⚠️ BREAKING ⚠️

* the `mysql`, `postgres`, `couchbase` and `memcache` session providers
are removed, use `file`, `db` or `redis` instead
* login-related cookies are renamed to `gitea_session` and
`gitea_remember`, if you'd like to use the old names, set `COOKIE_NAME`
and `COOKIE_REMEMBER_NAME` in app.ini

---------

Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-10-02 21:08:14 +02:00

70 lines
2.3 KiB
Go

// Copyright 2020 The Gitea Authors. All rights reserved.
// SPDX-License-Identifier: MIT
package auth
import (
"context"
"gitea.dev/models/db"
"gitea.dev/modules/timeutil"
"xorm.io/builder"
)
type Session struct {
Key string `xorm:"pk CHAR(16)"` // the limit is from legacy go-chi/session
Data []byte `xorm:"BLOB"` // on MySQL this has a maximum size of 64Kb
LastAccessTime timeutil.TimeStamp `xorm:"expiry"` // last access time, the field name is from legacy go-chi/session, we don't want to change it at the moment
}
const DbSessionLastAccessTime = "expiry" // maybe we can make a deeper clean up in the future, just keep this PR focused
func init() {
db.RegisterModel(new(Session))
}
// UpdateSession stores the data of the session with provided id, creating the session only if create is set
func UpdateSession(ctx context.Context, key string, data []byte, create bool) error {
session := &Session{Key: key, Data: data, LastAccessTime: timeutil.TimeStampNow()}
update := func() (int64, error) {
return db.GetEngine(ctx).ID(key).Cols("data", DbSessionLastAccessTime).Update(session)
}
if updated, err := update(); err != nil || updated > 0 || !create {
return err
}
insertErr := db.Insert(ctx, session)
if insertErr == nil {
return nil
}
// the row exists if a concurrent request inserted it, or if MySQL reported an unchanged row as not updated
if exist, err := db.Exist[Session](ctx, builder.Eq{"`key`": key}); err != nil || !exist {
return insertErr
}
_, err := update()
return err
}
func UpdateSessionLastAccessTime(ctx context.Context, key string) error {
_, err := db.GetEngine(ctx).ID(key).Cols(DbSessionLastAccessTime).Update(&Session{LastAccessTime: timeutil.TimeStampNow()})
return err
}
func GetSession(ctx context.Context, key string) (*Session, bool, error) {
return db.Get[Session](ctx, builder.Eq{"`key`": key})
}
// DestroySession destroys a session
func DestroySession(ctx context.Context, key string) error {
_, err := db.GetEngine(ctx).Delete(&Session{
Key: key,
})
return err
}
// CleanupSessions cleans up expired sessions
func CleanupSessions(ctx context.Context, maxLifetime int64) error {
_, err := db.GetEngine(ctx).Where(DbSessionLastAccessTime+" <= ?", timeutil.TimeStampNow().Add(-maxLifetime)).Delete(&Session{})
return err
}